CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2015-7557

    Last Modified: 12 Apr 2025

    The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via an odd number of elements in a coordinate pair in an SVG document.

    Published: 21 Dec 2015
    6.5
    Medium

    CVE-2015-8613

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulation support, allows local guest users to cause a denial of service (QEMU instance crash) via a crafted SCSI controller CTRL_GET_INFO command.

    Published: 21 Dec 2015
    7.5
    High

    CVE-2015-8618

    Last Modified: 12 Apr 2025

    The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes it easier for attackers to obtain private RSA keys via unspecified vectors.

    Published: 21 Dec 2015
    5.5
    Medium

    CVE-2015-7555

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in giffix.c in giffix in giflib 5.1.1 allows attackers to cause a denial of service (program crash) via crafted image and logical screen width fields in a GIF file.

    Published: 21 Dec 2015
    5
    Medium

    CVE-2015-8615

    Last Modified: 12 Apr 2025

    The hvm_set_callback_via function in arch/x86/hvm/irq.c in Xen 4.6 does not limit the number of printk console messages when logging the new callback method, which allows local HVM guest OS users to cause a denial of service via a large number of changes to the callback method (HVM_PARAM_CALLBACK_IRQ).

    Published: 21 Dec 2015
    9.8
    Critical

    CVE-2015-7755

    Last Modified: 21 Apr 2026

    Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.

    Published: 19 Dec 2015
    5
    Medium

    CVE-2015-7756

    Last Modified: 12 Apr 2025

    The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 makes it easier for remote attackers to discover the plaintext content of VPN sessions by sniffing the network for ciphertext data and conducting an unspecified decryption attack.

    Published: 19 Dec 2015
    5
    Medium

    CVE-2015-6429

    Last Modified: 12 Apr 2025

    The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote attackers to cause a denial of service (IPsec connection termination) via a crafted IKEv1 packet to a tunnel endpoint, aka Bug ID CSCuw08236.

    Published: 19 Dec 2015
    7.2
    High

    CVE-2015-6424

    Last Modified: 12 Apr 2025

    The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions and obtain single-user-mode root access via unspecified vectors, aka Bug ID CSCuu83985.

    Published: 18 Dec 2015
    7.2
    High

    CVE-2015-6426

    Last Modified: 12 Apr 2025

    Cisco Prime Network Services Controller 3.0 allows local users to bypass intended access restrictions and execute arbitrary commands via additional parameters to an unspecified command, aka Bug ID CSCus99427.

    Published: 18 Dec 2015
    5
    Medium

    CVE-2015-6427

    Last Modified: 12 Apr 2025

    Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection feature and avoid triggering Snort IDS rules via an SSL session that is mishandled after decryption, aka Bug ID CSCux53437.

    Published: 18 Dec 2015
    5
    Medium

    CVE-2015-6428

    Last Modified: 12 Apr 2025

    Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958.

    Published: 18 Dec 2015
    2.3
    Low

    CVE-2015-6556

    Last Modified: 12 Apr 2025

    EACommunicatorSrv.exe in the Framework Service in the client in Symantec Endpoint Encryption (SEE) before 11.1.0 allows remote authenticated users to discover credentials by triggering a memory dump.

    Published: 18 Dec 2015
    5.5
    Medium

    CVE-2016-1922

    Last Modified: 12 Apr 2025

    QEMU (aka Quick Emulator) built with the TPR optimization for 32-bit Windows guests support is vulnerable to a null pointer dereference flaw. It occurs while doing I/O port write operations via hmp interface. In that, 'current_cpu' remains null, which leads to the null pointer dereference. A user or process could use this flaw to crash the QEMU instance, resulting in DoS issue.

    Published: 18 Dec 2015
    4.3
    Medium

    CVE-2015-5204

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android before 1.3.0 allows remote attackers to inject arbitrary headers via CRLF sequences in the filename of an uploaded file.

    Published: 17 Dec 2015
    6
    Medium

    CVE-2015-8368

    Last Modified: 12 Apr 2025

    ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.

    Published: 17 Dec 2015
    7.2
    High

    CVE-2015-4027

    Last Modified: 12 Apr 2025

    The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users to gain privileges via a command parameter in the reporttemplate property in a params JSON object to api/addScan.

    Published: 17 Dec 2015
    7.5
    High

    CVE-2015-7527

    Last Modified: 12 Apr 2025

    lib/core.php in the Cool Video Gallery plugin 1.9 for WordPress allows remote attackers to execute arbitrary code via shell metacharacters in the "Width of preview image" and possibly other input fields in the "Video Gallery Settings" page.

    Published: 17 Dec 2015
    7.5
    High

    CVE-2015-8369

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execute arbitrary SQL commands via the rra_id parameter in a properties action to graph.php.

    Published: 17 Dec 2015
    7.5
    High

    CVE-2015-8600

    Last Modified: 12 Apr 2025

    The SysAdminWebTool servlets in SAP Mobile Platform allow remote attackers to bypass authentication and obtain sensitive information, gain privileges, or have unspecified other impact via unknown vectors, aka SAP Security Note 2227855.

    Published: 17 Dec 2015
    5
    Medium

    CVE-2015-8601

    Last Modified: 12 Apr 2025

    The Chat Room module 7.x-2.x before 7.x-2.2 for Drupal does not properly check permissions when setting up a websocket for chat messages, which allows remote attackers to bypass intended access restrictions and read messages from arbitrary Chat Rooms via unspecified vectors.

    Published: 17 Dec 2015
    3.5
    Low

    CVE-2015-8602

    Last Modified: 12 Apr 2025

    The Token Insert Entity module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote authenticated users with certain permissions to bypass intended access restrictions and possibly obtain sensitive information by inserting a token, which embeds a rendered entity in the main node.

    Published: 17 Dec 2015
    4.4
    Medium

    CVE-2015-8552

    Last Modified: 12 Apr 2025

    The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial of service (disk consumption) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and XEN_PCI_OP_enable_msi operations, aka "Linux pciback missing sanity checks."

    Published: 17 Dec 2015
    5.5
    Medium

    CVE-2015-8970

    Last Modified: 12 Apr 2025

    crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted application that does not supply a key, related to the lrw_crypt function in crypto/lrw.c.

    Published: 17 Dec 2015
    8.1
    High

    CVE-2015-5348

    Last Modified: 12 Apr 2025

    Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.

    Published: 17 Dec 2015
    6
    Medium

    CVE-2015-8551

    Last Modified: 12 Apr 2025

    The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer dereference and host OS crash) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and a crafted sequence of XEN_PCI_OP_* operations, aka "Linux pciback missing sanity checks."

    Published: 17 Dec 2015
    7.5
    High

    CVE-2015-8554

    Last Modified: 12 Apr 2025

    Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen-traditional (aka qemu-dm) device model, allows local x86 HVM guest administrators to gain privileges by leveraging a system with access to a passed-through MSI-X capable physical PCI device and MSI-X table entries, related to a "write path."

    Published: 17 Dec 2015
    9.8
    Critical

    CVE-2015-8880

    Last Modified: 12 Apr 2025

    Double free vulnerability in the format printer in PHP 7.x before 7.0.1 allows remote attackers to have an unspecified impact by triggering an error.

    Published: 17 Dec 2015
    7.5
    High

    CVE-2015-8619

    Last Modified: 20 Apr 2025

    The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write and application crash).

    Published: 17 Dec 2015
    8.2
    High

    CVE-2015-8550

    Last Modified: 12 Apr 2025

    Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.

    Published: 17 Dec 2015
    8.6
    High

    CVE-2015-8555

    Last Modified: 12 Apr 2025

    Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspecified vectors.

    Published: 17 Dec 2015
    9
    Critical

    CVE-2015-8358

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the element name of the "work" array parameter to admin/bitrix.mpbuilder_step2.php.

    Published: 16 Dec 2015
    6.5
    Medium

    CVE-2015-8357

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary files, and consequently obtain sensitive information or cause a denial of service, via a .. (dot dot) in the file parameter to admin/bitrix.xscan_worker.php.

    Published: 16 Dec 2015
    5
    Medium

    CVE-2015-8476

    Last Modified: 12 Apr 2025

    Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than CVE-2012-0796.

    Published: 16 Dec 2015
    7.5
    High

    CVE-2015-8562

    Last Modified: 12 Apr 2025

    Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015.

    Published: 16 Dec 2015
    6.8
    Medium

    CVE-2015-8563

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the com_templates component in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 16 Dec 2015
    7.5
    High

    CVE-2015-8564

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via directory traversal sequences in the XML install file in an extension package archive.

    Published: 16 Dec 2015
    7.5
    High

    CVE-2015-8565

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via unknown vectors.

    Published: 16 Dec 2015
    7.5
    High

    CVE-2015-8566

    Last Modified: 12 Apr 2025

    The Session package 1.x before 1.3.1 for Joomla! Framework allows remote attackers to execute arbitrary code via unspecified session values.

    Published: 16 Dec 2015
    6.8
    Medium

    CVE-2015-8580

    Last Modified: 12 Apr 2025

    Multiple use-after-free vulnerabilities in the (1) Print method and (2) App object handling in Foxit Reader before 7.2.2 and Foxit PhantomPDF before 7.2.2 allow remote attackers to execute arbitrary code via a crafted PDF document.

    Published: 16 Dec 2015
    Unknown

    CVE-2015-8581

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0779. Reason: This candidate is a duplicate of CVE-2016-0779. Notes: All CVE users should reference CVE-2016-0779 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Dec 2015
    6.4
    Medium

    CVE-2015-8578

    Last Modified: 12 Apr 2025

    AVG Internet Security 2015 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresses when protecting user-mode processes, which allows attackers to bypass the DEP and ASLR protection mechanisms via unspecified vectors.

    Published: 16 Dec 2015
    6.4
    Medium

    CVE-2015-8579

    Last Modified: 12 Apr 2025

    Kaspersky Total Security 2015 15.0.2.361 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresses when protecting user-mode processes, which allows attackers to bypass the DEP and ASLR protection mechanisms via unspecified vectors.

    Published: 16 Dec 2015
    2.6
    Low

    CVE-2015-8577

    Last Modified: 12 Apr 2025

    The Buffer Overflow Protection (BOP) feature in McAfee VirusScan Enterprise before 8.8 Patch 6 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresses on 32-bit platforms when protecting another application, which allows attackers to bypass the DEP and ASLR protection mechanisms via unspecified vectors.

    Published: 16 Dec 2015
    5
    Medium

    CVE-2015-6425

    Last Modified: 12 Apr 2025

    The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10.5(0.98000.88) allows remote attackers to cause a denial of service (subsystem outage) via invalid session tokens, aka Bug ID CSCul83786.

    Published: 16 Dec 2015
    7.5
    High

    CVE-2015-5330

    Last Modified: 12 Apr 2025

    ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, which allows remote attackers to obtain sensitive information from daemon heap memory by sending crafted packets and then reading (1) an error message or (2) a database value.

    Published: 16 Dec 2015
    10
    Critical

    CVE-2015-7201

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 16 Dec 2015
    5
    Medium

    CVE-2015-7208

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers.

    Published: 16 Dec 2015
    6.8
    Medium

    CVE-2015-7213

    Last Modified: 12 Apr 2025

    Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 on 64-bit platforms allows remote attackers to execute arbitrary code via a crafted MP4 video file that triggers a buffer overflow.

    Published: 16 Dec 2015
    6.8
    Medium

    CVE-2015-7216

    Last Modified: 12 Apr 2025

    The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted JPEG 2000 image.

    Published: 16 Dec 2015